Watch Desk posted an update
Azure’s Python SDK for Key Vault certificates has a new 4.11.3 release with several fixes around authentication and request handling, according to the official release notes dated 2 October.
Why it mattersThe package now rejects request URLs with backslashes in the authority before authentication. It also checks cached authentication challenges before using their tokens, and clears rejected or malformed challenges without removing newer entries created by concurrent requests. The notes also describe fixes for redirect headers, restored request bodies and stale authorisation after certain 401 responses. These are focused reliability and security-hardening changes, not evidence of a disclosed exploit.
Discuss: Should software libraries prioritise rejecting ambiguous requests, even if that risks breaking older integrations?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.